CVE-2023-48275
The Widgets for Google Reviews plugin prior to version 11.1 contains an arbitrary file upload vulnerability in the feature_request.php file that lacks proper file type validation. Attackers with editor-level privileges or higher can exploit this flaw to upload malicious files to the server, potentially enabling remote code execution depending on server conditions and timing of file operations. The vulnerability exists because the plugin does not adequately verify uploaded file types before processing them.
Based on public CVE data (MITRE/NVD).